6 days ago
US Disrupts Chinese QTFY Botnet Targeting Critical Infrastructure
US officials say they stopped a Chinese-linked hacking network called QTFY.
The network used two tools, QScan and QTRouter.
QScan searched for internet-connected devices such as routers and cameras and infected some of them.
QTRouter then used those devices to make attacks look as if they came from somewhere other than China.
Officials said the network targeted important US organizations and other sensitive networks.
They seized internet domains that the tools needed to communicate and work.
This made the two platforms unusable, according to the Justice Department.
China denies wrongdoing, while US officials describe the operation as part of a wider cyber-espionage threat.
The US Justice Department and FBI seized domains used by QTFY’s QScan and QTRouter hacking platforms.
US authorities attributed QTFY to Nanjing Xinjiuwei Network Technology Company, which they said supported Chinese government customers.
QScan infected internet-connected devices, while QTRouter used compromised devices, proxy services, and leased servers to hide hackers’ origins.
The network was reportedly active since 2018 and targeted US agencies, critical infrastructure, hospitals, telecommunications providers, and defense contractors.
The article says China denies wrongdoing and places the QTFY operation within a broader pattern of alleged Chinese cyber-espionage and influence activities.
- Who
- The US Justice Department and FBI disrupted a network attributed to the Chinese state-sponsored QTFY group and Nanjing Xinjiuwei Network Technology Company.
- What
- Authorities seized domains supporting QScan and QTRouter, hacking platforms allegedly used to compromise devices and target sensitive networks.
- Where
- The operation used devices and servers around the world and targeted US critical infrastructure and other sensitive networks.
- When
- The disruption was announced on August 26, 2026; officials said QTFY had been active since 2018.
- Why
- The seizures were intended to deny malicious cyber actors access to the platforms and make the malware-dependent services inoperable.
US Authorities’ Account
China’s Position
Responsibility for the network
US Authorities’ Account
The Justice Department and FBI attributed QTFY to Nanjing Xinjiuwei Network Technology Company and said the group supported Chinese government customers, including the Ministry of State Security and the People’s Liberation Army.
China’s Position
The article states that China denies wrongdoing but does not provide a detailed Chinese response to the QTFY allegations.
Purpose of the activity
US Authorities’ Account
US officials described QScan and QTRouter as tools used to target critical infrastructure and sensitive networks while concealing the source of intrusions.
China’s Position
China rejects the broader allegations of covert cyber-espionage and influence activities presented in the article.
Key facts
- Disruption method
- Court-authorized seizures of domains used by QScan and QTRouter.
- Attributed group
- QTFY, described by US authorities as a Chinese state-sponsored cyber-espionage group.
- Associated company
- Nanjing Xinjiuwei Network Technology Company, based in China.
- QScan function
- Scanning and automatically infecting internet-connected devices globally.
- QTRouter function
- Using compromised IoT devices, commercial proxy-service devices, and leased virtual private servers to obscure attack origins.
- Reported activity period
- The network was active from at least 2018 through 2026, according to the article.
- Reported targets
- NASA, the Federal Reserve, the Department of Energy, the Department of Justice, health agencies, the Senate, hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
Quotes
US Justice Department and FBI
US law-enforcement agencies announcing the court-authorized disruption of QTFY’s hacking platforms
“The Justice Department and FBI announced court-authorised domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.”
opindia.com











